Live data from Hacker News

British engineering giant Arup revealed as $25M deepfake scam victim

cnn.com

71–80 of 109 posts

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#71

Earlier quoted context omitted.

we're probably ~10 years away from replicants. in 20years there's going to be millions of tesla humanoid robots all over the place

We’ve had millions of robotaxis since 2017

do you have actual numbers? thought it was a couple thousand

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#72
post #44
post #41

The real issue here is a lack of proper risk controls around business processes involving money. Regardless of if it’s £3 for a coffee or £25m for a Secret acquisition there should be an agreed process that everyone involved in business transactions should be aware of so that if they are suddenly privy to a deal they can navigate and validate the authenticity of their involvement.

This brings up an interesting “risk control” that one of my tech investors personally implemented with his family, in case a audio/video version of him ever asks to do anything crazy: secret passwords, agreed upon in person.

Technically Signal solves this problem with safety codes.

The UI really could stand to be more assertive about what they mean though.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#73
post #45
post #2

I said this over a year ago elsewhere: Electronic engineers spent decades overcoming thermal noise floors so that humans could communicate over vast distances with small amounts of energy. AI researchers, in a few short years, undid all that by making computer-generated chatter and images indistinguishable from messages sent by humans. Until such a time as we live in a Bladerunner-like world of Replicants, being in-p…

When I'm on a company video call, the people I'm meeting with are logged into their company accounts, through the fancy company authentication system. Large warnings are displayed if there are any external participants, and I wouldn't be surprised if it's possible to disable the ability to even have guests. Third-party video conference software is banned and blocked from installation on work computers. I am not in th…

I imagine the people at Arup who fell for the scam were confident in their systems protecting them too.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#74
post #45

Earlier quoted context omitted.

When I'm on a company video call, the people I'm meeting with are logged into their company accounts, through the fancy company authentication system. Large warnings are displayed if there are any external participants, and I wouldn't be surprised if it's possible to disable the ability to even have guests. Third-party video conference software is banned and blocked from installation on work computers. I am not in th…

If I was the attacker, I'd use credential-stuffing or something to get access to some random employee's account. Doesn't have to be anyone important. Then I'd set up a short-notice multi-way meeting between the target, the CEO and the hacked account. The deepfake 'CEO' then turns up with no alarms raised, except one wrong name - easily dismissed as a glitch, or an assistant having booked the meeting.

$10k/week in crypto lets you easily 'hack' a random corporate account

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#76
post #45

Earlier quoted context omitted.

When I'm on a company video call, the people I'm meeting with are logged into their company accounts, through the fancy company authentication system. Large warnings are displayed if there are any external participants, and I wouldn't be surprised if it's possible to disable the ability to even have guests. Third-party video conference software is banned and blocked from installation on work computers. I am not in th…

If I was the attacker, I'd use credential-stuffing or something to get access to some random employee's account. Doesn't have to be anyone important. Then I'd set up a short-notice multi-way meeting between the target, the CEO and the hacked account. The deepfake 'CEO' then turns up with no alarms raised, except one wrong name - easily dismissed as a glitch, or an assistant having booked the meeting.

So your method assumes you can easily take over an employee account? Isn't that the hard part?

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#77
Learned recently my mid sized company was also targeted. The CFO received first a (fake) call from a lawyer asking to confirm a transaction, then later a deep faked voicemail from the co founder mentioning that same transaction. It apparently all sounded very real. The attacks are becoming very targeted, customized and elaborate. Very far from the Nigerian prince emails written in poor English...

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#78
post #2

I said this over a year ago elsewhere: Electronic engineers spent decades overcoming thermal noise floors so that humans could communicate over vast distances with small amounts of energy. AI researchers, in a few short years, undid all that by making computer-generated chatter and images indistinguishable from messages sent by humans. Until such a time as we live in a Bladerunner-like world of Replicants, being in-p…

Not that it changes your point much, but AI research also took decades. It’s just that the last few years are when all these milestones were achieved

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#79
I think the underlying problem is cultural: people have been conditioned to expect others to authenticate them (give me the last 4 digits of your SSN, tell me the last two transactions on your account), BUT they haven't been told they need to authenticate others. They just aren't thinking "how do I know this is who I think it is? How do I know they haven't been kidnapped?".

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#80

What I find strange about this is you dont need it to be "deepfake". Just an inside job. If a large company allows a single employee to transfer millions to a new bank account/vendor that has no history, on "their belief" the instruction came from an approved person (i.e. their boss, CFO etc) - that company has major governance issues that are not related to deepfake. Imagine the more simple scenario - an employee tr…

You're the only commenter using critical analysis, everyone else is just flapping their jaws. I hate discussing deepfakes. I'm one of the original patent holders of automated actor replacement technology. I developed it for personalized advertising, after having been an actor replacement specialist in a bunch of VFX film you probably saw. I spent from 2002 to '08 creating a VFX pipeline, with global patent protection…

[deleted]
Post reply on HN